Security & Compliance
Security & Compliance
Last updated February 26, 2026 · Version 2026-07-11
Access & authentication
- Unique Login Credentials for every Licensed User; no shared accounts.
- Passwords stored using industry-standard salted hashes; never in plaintext.
- Multi-factor authentication (MFA) available for all users and enforced for administrators.
- Role-based access control on all Platform surfaces, applied server-side.
- Row-level security in the database restricts data to the account it belongs to.
- Administrative access to production requires MFA and is logged.
Encryption
- Data in transit is protected with TLS 1.2 or higher.
- Data at rest is encrypted using AES-256 or equivalent managed by our cloud providers.
- Secrets and API keys are stored in a managed secret store with scoped access.
Platform & hosting
The Platform runs on reputable cloud infrastructure providers in the United States. We use managed database services with automated backups and point-in-time recovery, and managed edge/CDN services for global delivery. Production is isolated from development and staging environments.
Logging & monitoring
- Application, authentication, and administrative actions are logged.
- Anomaly and error monitoring on production services with on-call rotation.
- Regular review of access reports and audit trails.
Vulnerability management
- Dependency scanning on every build; prioritized remediation of critical findings.
- Regular security review of platform code and infrastructure configuration.
- Coordinated disclosure via security@g3ai.io; we do not pursue good-faith researchers.
Incident response
We maintain a documented incident-response plan covering detection, containment, eradication, recovery, and post-incident review. Customers are notified of a personal data breach affecting their account without undue delay and, in any case, within seventy-two (72) hours of confirmation, as detailed in the DPA.
Backups & recovery
- Automated daily database backups with point-in-time recovery.
- Documented recovery procedures, tested periodically.
Personnel
- Background checks for personnel with access to production systems, where permitted by law.
- Confidentiality obligations in every employment and contractor agreement.
- Security-awareness onboarding and annual refreshers.
Compliance posture
G3 AI aligns its controls to widely recognized frameworks, including NIST CSF and the SOC 2 Trust Services Criteria, and honors data-subject rights under GDPR/UK GDPR and CCPA/CPRA. Formal certifications, audit reports, and industry-specific attestations (such as SOC 2 Type II, HIPAA BAAs, or ISO 27001) are provided under NDA when available and required for a specific engagement. Contact security@g3ai.io to request our current security documentation package.
Nothing on this page constitutes a certification. Where a specific certification is not yet obtained, we say so directly rather than imply otherwise.
Shared responsibility
Customers are responsible for: choosing which data to upload; configuring roles and permissions for their Licensed Users; enforcing MFA on their side; reviewing outputs before relying on them; and honoring their own contractual, statutory, and regulatory obligations toward the people whose data they submit.
Contact
Security questions and reports: security@g3ai.io. Privacy questions: privacy@g3ai.io.
Questions about this document? Email legal@g3ai.io.

